Skip to content

Class: MigrationStateManager ​

Defined in: migrate.ts:421

Tracks PQC migration state for a collection of keys, with validation, history and an audit trail. Storage-agnostic: you provide the MigrationStore. Convert to and from quantum-safe-py's store layout with exportToPyStore / importFromPyStore.

Valid forward transitions: classical_only → hybrid_transition → pqc_preferred → pqc_only. Backward transitions (hybrid_transition → classical_only, pqc_preferred → hybrid_transition) need allowBackward: true and a reason; pqc_only is terminal.

Concurrency. Each key's whole history is one document, written with a single compare-and-set. With a store that implements compareAndSet atomically, concurrent transitions from any number of processes are safe: exactly one wins and the others get a stale-state error. Without it, the manager only serialises inside this process (see MigrationStateManager.crossProcessSafe).

Constructors ​

Constructor ​

new MigrationStateManager(store): MigrationStateManager

Defined in: migrate.ts:425

Parameters ​

store ​

MigrationStore

Returns ​

MigrationStateManager

Accessors ​

crossProcessSafe ​

Get Signature ​

get crossProcessSafe(): boolean

Defined in: migrate.ts:430

True if the store provides compare-and-set, so transitions are atomic across processes (given a correct store).

Returns ​

boolean

Methods ​

getCurrentRecord() ​

getCurrentRecord(keyId): Promise<MigrationRecord | undefined>

Defined in: migrate.ts:511

Parameters ​

keyId ​

string

Returns ​

Promise<MigrationRecord | undefined>


getCurrentState() ​

getCurrentState(keyId): Promise<MigrationState | undefined>

Defined in: migrate.ts:515

Parameters ​

keyId ​

string

Returns ​

Promise<MigrationState | undefined>


getHistory() ​

getHistory(keyId): Promise<MigrationRecord[]>

Defined in: migrate.ts:520

Full history, oldest first.

Parameters ​

keyId ​

string

Returns ​

Promise<MigrationRecord[]>


importHistory() ​

importHistory(keyId, records): Promise<void>

Defined in: migrate.ts:489

Imports a complete, previously exported history for a key that has no records yet (used by importFromPyStore). The chain is validated: each record's fromState must equal the previous toState and every step must be a legal transition.

Parameters ​

keyId ​

string

records ​

readonly MigrationRecord[]

Returns ​

Promise<void>


keyIds() ​

keyIds(): Promise<string[]>

Defined in: migrate.ts:526

All key ids that have any history, sorted. A full scan: keep a secondary index in production.

Returns ​

Promise<string[]>


keysByState() ​

keysByState(state): Promise<string[]>

Defined in: migrate.ts:533

Key ids currently in state, sorted. A full scan.

Parameters ​

state ​

MigrationState

Returns ​

Promise<string[]>


migrationProgress() ​

migrationProgress(): Promise<Record<MigrationState, number>>

Defined in: migrate.ts:545

Counts of keys per state.

Returns ​

Promise<Record<MigrationState, number>>


needsMigration() ​

needsMigration(): Promise<string[]>

Defined in: migrate.ts:540

Key ids that are still classical_only.

Returns ​

Promise<string[]>


transition() ​

transition(opts): Promise<MigrationRecord>

Defined in: migrate.ts:435

Records a transition.

Parameters ​

opts ​

TransitionOptions

Returns ​

Promise<MigrationRecord>

Throws ​

for invalid, stale or contended transitions.

Apache-2.0.